From: Stefan Hanreich <s.hanreich@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH pve-network v2 22/34] api2: add prefix list module
Date: Wed, 1 Apr 2026 16:39:31 +0200 [thread overview]
Message-ID: <20260401143957.386809-23-s.hanreich@proxmox.com> (raw)
In-Reply-To: <20260401143957.386809-1-s.hanreich@proxmox.com>
Contains the CRUD functionality for prefix lists:
GET /prefix-lists - lists all prefix lists
GET /prefix-lists/<id> - get prefix list <id>
POST /prefix-lists - create a new prefix list
PUT /prefix-lists/<id> - update prefix list <id>
DELETE /prefix-lists/<id> - delete prefix list <id>
Signed-off-by: Stefan Hanreich <s.hanreich@proxmox.com>
---
src/PVE/API2/Network/SDN.pm | 7 +
src/PVE/API2/Network/SDN/Makefile | 11 +-
src/PVE/API2/Network/SDN/PrefixLists.pm | 254 ++++++++++++++++++++++++
3 files changed, 270 insertions(+), 2 deletions(-)
create mode 100644 src/PVE/API2/Network/SDN/PrefixLists.pm
diff --git a/src/PVE/API2/Network/SDN.pm b/src/PVE/API2/Network/SDN.pm
index cc5ac25..778a29b 100644
--- a/src/PVE/API2/Network/SDN.pm
+++ b/src/PVE/API2/Network/SDN.pm
@@ -22,6 +22,7 @@ use PVE::API2::Network::SDN::Zones;
use PVE::API2::Network::SDN::Ipams;
use PVE::API2::Network::SDN::Dns;
use PVE::API2::Network::SDN::Fabrics;
+use PVE::API2::Network::SDN::PrefixLists;
use base qw(PVE::RESTHandler);
@@ -55,6 +56,11 @@ __PACKAGE__->register_method({
path => 'fabrics',
});
+__PACKAGE__->register_method({
+ subclass => "PVE::API2::Network::SDN::PrefixLists",
+ path => 'prefix-lists',
+});
+
__PACKAGE__->register_method({
name => 'index',
path => '',
@@ -87,6 +93,7 @@ __PACKAGE__->register_method({
{ id => 'ipams' },
{ id => 'dns' },
{ id => 'fabrics' },
+ { id => 'prefix-lists' },
];
return $res;
diff --git a/src/PVE/API2/Network/SDN/Makefile b/src/PVE/API2/Network/SDN/Makefile
index 2624d9a..4349c17 100644
--- a/src/PVE/API2/Network/SDN/Makefile
+++ b/src/PVE/API2/Network/SDN/Makefile
@@ -1,5 +1,12 @@
-SOURCES=Vnets.pm Zones.pm Controllers.pm Subnets.pm Ipams.pm Dns.pm Ips.pm Fabrics.pm
-
+SOURCES=Vnets.pm\
+ Zones.pm\
+ Controllers.pm\
+ Subnets.pm\
+ Ipams.pm\
+ Dns.pm\
+ Ips.pm\
+ Fabrics.pm\
+ PrefixLists.pm
PERL5DIR=${DESTDIR}/usr/share/perl5
diff --git a/src/PVE/API2/Network/SDN/PrefixLists.pm b/src/PVE/API2/Network/SDN/PrefixLists.pm
new file mode 100644
index 0000000..00a6d14
--- /dev/null
+++ b/src/PVE/API2/Network/SDN/PrefixLists.pm
@@ -0,0 +1,254 @@
+package PVE::API2::Network::SDN::PrefixLists;
+
+use strict;
+use warnings;
+
+use PVE::Exception qw(raise_param_exc);
+use PVE::JSONSchema qw(get_standard_option);
+use PVE::Tools qw(extract_param);
+
+use PVE::RESTHandler;
+use base qw(PVE::RESTHandler);
+
+__PACKAGE__->register_method({
+ name => 'list_prefix_lists',
+ path => '',
+ method => 'GET',
+ permissions => {
+ description =>
+ "Only returns prefix list entries where you have 'Sys.Audit' or 'Sys.Modify' permissions.",
+ user => 'all',
+ },
+ description => "List Prefix Lists",
+ parameters => {
+ properties => {
+ running => {
+ type => 'boolean',
+ optional => 1,
+ description => "Display running config.",
+ },
+ pending => {
+ type => 'boolean',
+ optional => 1,
+ description => "Display pending config.",
+ },
+ },
+ },
+ returns => {
+ type => 'array',
+ items => {
+ type => "object",
+ properties => {},
+ },
+ links => [{ rel => 'child', href => "{id}" }],
+ },
+ code => sub {
+ my ($param) = @_;
+
+ my $pending = extract_param($param, 'pending');
+ my $running = extract_param($param, 'running');
+
+ my $digest;
+ my $prefix_lists;
+
+ if ($pending) {
+ my $current_config = PVE::Network::SDN::PrefixLists::config();
+ my $running_config = PVE::Network::SDN::PrefixLists::config(1);
+
+ my $pending_prefix_lists = PVE::Network::SDN::pending_config(
+ { 'prefix-lists' => { ids => $running_config->list() } },
+ { ids => $current_config->list() },
+ 'prefix-lists',
+ );
+
+ $digest = $current_config->digest();
+ $prefix_lists = $pending_prefix_lists->{ids};
+ } elsif ($running) {
+ $prefix_lists = PVE::Network::SDN::PrefixLists::config(1)->list();
+ } else {
+ my $current_config = PVE::Network::SDN::PrefixLists::config();
+
+ $digest = $current_config->digest();
+ $prefix_lists = $current_config->list();
+ }
+
+ my $rpcenv = PVE::RPCEnvironment::get();
+ my $authuser = $rpcenv->get_user();
+ my $prefix_list_privs = ['SDN.Audit'];
+
+ my @res;
+ for my $prefix_list_id (sort keys $prefix_lists->%*) {
+ next
+ if !$rpcenv->check_any(
+ $authuser,
+ "/prefix-lists/$prefix_list_id",
+ $prefix_list_privs,
+ 1,
+ );
+ $prefix_lists->{$prefix_list_id}->{digest} = $digest if $digest;
+ push @res, $prefix_lists->{$prefix_list_id};
+ }
+
+ return \@res;
+ },
+});
+
+__PACKAGE__->register_method({
+ name => 'get_prefix_list_entry',
+ path => '{id}',
+ method => 'GET',
+ permissions => {
+ check => ['perm', '/sdn/prefix-lists/{id}', ['SDN.Audit']],
+ },
+ description => "Get Prefix List",
+ parameters => {
+ properties => {
+ id => get_standard_option('pve-sdn-prefix-list-id'),
+ },
+ },
+ returns => {
+ type => "object",
+ properties => {},
+ },
+ code => sub {
+ my ($param) = @_;
+
+ my $prefix_list_id = extract_param($param, 'id');
+ my $prefix_list_entry = PVE::Network::SDN::PrefixLists::config()->get($prefix_list_id);
+
+ raise_param_exc({ 'id' => "$prefix_list_id doesn't exist" })
+ if !$prefix_list_entry;
+
+ return $prefix_list_entry;
+ },
+});
+
+__PACKAGE__->register_method({
+ name => 'create_prefix_list_entry',
+ path => '',
+ method => 'POST',
+ permissions => {
+ check => ['perm', '/sdn/prefix-lists', ['SDN.Allocate']],
+ },
+ description => "Create Prefix List",
+ parameters => {
+ properties => {
+ digest => get_standard_option('pve-config-digest'),
+ 'lock-token' => get_standard_option('pve-sdn-lock-token'),
+ PVE::Network::SDN::PrefixLists::prefix_list_properties(0)->%*,
+ },
+ },
+ returns => {
+ type => "null",
+ },
+ code => sub {
+ my ($param) = @_;
+
+ my $lock_token = extract_param($param, 'lock-token');
+
+ PVE::Network::SDN::lock_sdn_config(
+ sub {
+ my $config = PVE::Network::SDN::PrefixLists::config();
+
+ my $digest = extract_param($param, 'digest');
+ PVE::Tools::assert_if_modified($config->digest(), $digest) if $digest;
+
+ $config->create($param);
+ PVE::Network::SDN::PrefixLists::write_config($config);
+ },
+ "creating prefix list failed",
+ $lock_token,
+ );
+
+ return;
+ },
+});
+
+__PACKAGE__->register_method({
+ name => 'update_prefix_list_entry',
+ path => '{id}',
+ method => 'PUT',
+ permissions => {
+ check => ['perm', '/sdn/prefix-lists/{id}', ['SDN.Allocate']],
+ },
+ description => "Update Prefix List",
+ parameters => {
+ properties => {
+ digest => get_standard_option('pve-config-digest'),
+ 'lock-token' => get_standard_option('pve-sdn-lock-token'),
+ PVE::Network::SDN::PrefixLists::prefix_list_properties(1)->%*,
+ },
+ },
+ returns => {
+ type => "null",
+ },
+ code => sub {
+ my ($param) = @_;
+
+ my $lock_token = extract_param($param, 'lock-token');
+
+ PVE::Network::SDN::lock_sdn_config(
+ sub {
+ my $config = PVE::Network::SDN::PrefixLists::config();
+
+ my $digest = extract_param($param, 'digest');
+ PVE::Tools::assert_if_modified($config->digest(), $digest) if $digest;
+
+ my $prefix_list_id = extract_param($param, 'id');
+ my $delete = extract_param($param, 'delete');
+
+ $config->update($prefix_list_id, $param, $delete);
+ PVE::Network::SDN::PrefixLists::write_config($config);
+ },
+ "updating prefix list failed",
+ $lock_token,
+ );
+
+ return;
+ },
+});
+
+__PACKAGE__->register_method({
+ name => 'delete_prefix_list_entry',
+ path => '{id}',
+ method => 'DELETE',
+ permissions => {
+ check => ['perm', '/sdn/prefix-lists/{id}', ['SDN.Allocate']],
+ },
+ description => "Delete Prefix List",
+ parameters => {
+ properties => {
+ digest => get_standard_option('pve-config-digest'),
+ 'lock-token' => get_standard_option('pve-sdn-lock-token'),
+ id => get_standard_option('pve-sdn-prefix-list-id'),
+ },
+ },
+ returns => {
+ type => "null",
+ },
+ code => sub {
+ my ($param) = @_;
+
+ my $lock_token = extract_param($param, 'lock-token');
+
+ PVE::Network::SDN::lock_sdn_config(
+ sub {
+ my $config = PVE::Network::SDN::PrefixLists::config();
+
+ my $digest = extract_param($param, 'digest');
+ PVE::Tools::assert_if_modified($config->digest(), $digest) if $digest;
+
+ my $prefix_list_id = extract_param($param, 'id');
+
+ $config->delete($prefix_list_id);
+ PVE::Network::SDN::PrefixLists::write_config($config);
+ },
+ "deleting prefix list failed",
+ $lock_token,
+ );
+
+ return;
+ },
+});
+
+1;
--
2.47.3
next prev parent reply other threads:[~2026-04-01 14:45 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-04-01 14:39 [PATCH access-control/cluster/network/proxmox{-ve-rs,-perl-rs} v2 00/34] Add support for route maps / prefix lists to SDN Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-cluster v2 01/34] cfs: add 'sdn/route-maps.cfg' to observed files Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-cluster v2 02/34] cfs: add 'sdn/prefix-lists.cfg' " Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-access-control v2 03/34] permissions: add ACL path for prefix-lists and route-maps Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 04/34] frr: add constructor to prefix list name Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 05/34] sdn-types: add common route-map helper types Stefan Hanreich
2026-04-02 13:36 ` Wolfgang Bumiller
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 06/34] frr: change order type to u16 Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 07/34] frr: implement routemap match/set statements via adjacent tagging Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 08/34] frr: implement support for call and exit action Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 09/34] frr-templates: change route maps template to adapt to new frr types Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 10/34] ve-config: fabrics: adapt frr config generation Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 11/34] ve-config: add prefix list section config Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 12/34] ve-config: frr: implement frr config generation for prefix lists Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 13/34] ve-config: add route map section config Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 14/34] ve-config: frr: implement frr config generation for route maps Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 15/34] ve-config: add prefix lists integration tests Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-ve-rs v2 16/34] ve-config: add route maps " Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-perl-rs v2 17/34] pve-rs: sdn: add route maps module Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-perl-rs v2 18/34] pve-rs: sdn: add prefix lists module Stefan Hanreich
2026-04-01 14:39 ` [PATCH proxmox-perl-rs v2 19/34] sdn: add prefix list / route maps to frr config generation helper Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 20/34] controller: bgp: evpn: adapt to new match / set frr config syntax Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 21/34] sdn: add prefix lists module Stefan Hanreich
2026-04-01 14:39 ` Stefan Hanreich [this message]
2026-04-01 14:39 ` [PATCH pve-network v2 23/34] sdn: add route map module Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 24/34] api2: add route maps api module Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 25/34] api2: add route map module Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 26/34] api2: add route map entry module Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 27/34] evpn controller: add route_map_{in,out} parameter Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 28/34] bgp controller: allow configuring custom route maps Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 29/34] sdn: change detection for route maps / prefix lists Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 30/34] sdn: generate route map / prefix list configuration on sdn apply Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 31/34] tests: add simple route map test case Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 32/34] tests: add bgp evpn route map/prefix list testcase Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 33/34] tests: add route map with prefix " Stefan Hanreich
2026-04-01 14:39 ` [PATCH pve-network v2 34/34] tests: add exit node with custom route map testcase Stefan Hanreich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260401143957.386809-23-s.hanreich@proxmox.com \
--to=s.hanreich@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox